Skip to main content

API Reference

All Flo API endpoints are versioned and documented via Swagger/OpenAPI. This page groups the surface by area; for each group it lists the base path, the typical auth level and representative endpoints.

API Structure​

APIBase PathAuthDescription
Private/api/v1/...Cookie session (or OpenIddict bearer)Main application API
Public/api/public/v1/...API token or noneExternal integrations and public site
Public (misc)/api/v1/public/..., /api/v1/user/...API token, none, or OpenIddict bearerOTP auth, user upsert, immobili access, /user/me
Swagger/swaggerNo (development only)Interactive API documentation
Health/health, /health/ready, /health/commerceNoLiveness/readiness probes

Auth levels used below: none (anonymous), User, Pro, Admin, SuperAdmin, token (public API token with the named permission).

Endpoint Groups​

GroupBase pathTypical auth
Authentication/api/v1/auth, /api/v1/public/auth/otp, /api/v1/oauth, /api/v1/external-authnone / cookie
Users/api/v1/usersUser / Pro / Admin / SuperAdmin
Activities, Services & Bookings/api/v1/activitiesUser / Pro / Admin
Locations/api/v1/locationsUser / Admin
Closures/api/v1/scUser / Admin
Subscriptions/api/v1/studio-plans, /api/v1/client-subscriptions, /api/v1/subscription-plans, /api/v1/subscription-features, /api/v1/myPro / Admin / SuperAdmin
Payments/api/v1/paymentsUser / Admin / none (webhooks)
Commerce/api/v1/commerceUser / Admin
Invoicing/api/v1/einvoicing/*Admin / SuperAdmin
Blog/api/v1/articles, /api/v1/categories, /api/v1/authors, /api/v1/comments, /api/v1/strapi-commentsPro / Admin
Immobili/api/v1/immobiles, /api/v1/immobili/*Pro
Catalogo/api/v1/catalog-itemsPro
Galleries & dynamic content/api/v1/galleriesUser / Pro / SuperAdmin
Website states/api/v1/website-statesPro
Forms/api/v1/formsPro / Admin / SuperAdmin
Contacts/api/v1/contactsPro
Communication & Newsletter/api/v1/newsletterPro / Admin / SuperAdmin
Translations/api/v1/translationPro / Admin
Branding/api/v1/admin/branding, /api/v1/brand-kit, /api/v1/config-editorPro / SuperAdmin
Analytics/api/v1/analytics, /api/v1/business-analytics, /api/v1/web-analyticsAdmin / Pro
Settings/api/v1/admin, /api/v1/api-tokens, /api/v1/webhook-configs, /api/v1/cors-origins, /api/v1/audit-logs, /api/v1/auth-events, /api/v1/email-delivery-logs, /api/v1/logs, /api/v1/quotas, /api/v1/maintenanceAdmin / SuperAdmin / maintenance key
Diagnostics/api/v1/diagnostics, /healthauthenticated / SuperAdmin

Authentication​

MethodEndpointAuthDescription
POST/api/v1/auth/loginnonePassword login (rate-limited)
POST/api/v1/auth/registernoneRegistration (gated by enable_registration)
GET/api/v1/auth/verify-sessionnoneVerify the current session cookie
POST/api/v1/auth/logoutcookieSign out
POST/api/v1/auth/forgot-passwordnoneRequest password reset
POST/api/v1/auth/reset-passwordnoneReset password with token
POST/api/v1/auth/set-passwordnone (action token)Set password from an activation link
POST/api/v1/auth/enable-usernone (action token)Enable account from an activation link
POST/api/v1/auth/resend-confirmationAdminResend email confirmation
POST/api/v1/auth/resend-password-creationAdminResend password-creation email
POST/api/v1/public/auth/otp/requestnoneRequest an OTP code (Turnstile)
POST/api/v1/public/auth/otp/validatenoneVerify an OTP code
POST/api/v1/public/auth/otp/resendnoneResend an OTP code (Turnstile)
GET/api/v1/public/auth/otp/check-emailnoneCheck whether an email can receive an OTP
GET/POST/api/v1/oauth/authorizenoneOIDC authorization endpoint (PKCE)
POST/api/v1/oauth/tokennoneOIDC token endpoint
GET/POST/api/v1/oauth/userinfobearerOIDC userinfo
GET/POST/api/v1/oauth/logoutnoneOIDC end-session
GET/api/v1/external-auth/confignoneSocial-login availability (Google/Apple flags)
POST/api/v1/external-auth/googlenoneGoogle sign-in
POST/api/v1/external-auth/applenoneApple sign-in
GET/PUT/api/v1/external-auth-settingsSuperAdminSocial-login client ids
GET/api/v1/user/meOpenIddict bearerCurrent user profile for token clients

Users​

MethodEndpointAuthDescription
GET/api/v1/usersPro/AdminList users (access-policy scoped)
POST/api/v1/usersAdminCreate user
GET/api/v1/users/{id}self/Pro/AdminUser detail
GET/api/v1/users/check-availabilityPro/AdminEmail/phone availability check
GET/api/v1/users/{id}/full-detailSuperAdminFull profile (sensitive)
GET/api/v1/users/{id}/deletion-impactAdminWhat deleting the user would touch
GET/api/v1/users/me/password-statusUserWhether a password change is forced
PUT/api/v1/users/me/preferred-content-languageUserPreferred content language
GET/api/v1/users/prosUserList professionals
GET/api/v1/users/user/{userId}/bookingsUserA user's bookings
POST/api/v1/users/add-entriesAdminGrant subscription entries
GET/PUT/api/v1/users/subscriptions, /user/{userId}/subscriptionsAdminSubscription entitlements
POST/api/v1/users/{id}/deleteAdminDelete user
GET/api/v1/users/gdpr-export?userId=self/AdminGDPR data export (JSON download)
POST/api/v1/users/gdpr-deleteself/AdminGDPR deletion (email + password confirmation)
POST/api/v1/users/{id}/enableAdminEnable/disable user
POST/api/v1/users/{id}/set-pro / set-adminAdminRole change
POST/api/v1/users/{id}/set-superadminSuperAdminGrant/revoke SuperAdmin
POST/api/v1/users/{id}/change-passwordAdminForce a password change
GET/api/v1/users/professionals, /{id}/professional-profileUserProfessional profiles
GET/PUT/api/v1/users/{id}/professional-profileProEdit professional profile
GET/api/v1/users/{id}/servicesProServices assigned to a professional
POST/api/v1/users/{userId}/photosProAdd profile photos

Activities, Services, Schedules & Bookings​

Base: /api/v1/activities.

MethodEndpointAuthDescription
GET/api/v1/activities/activitiesUserList activities (filterBookable, includeHidden, locale)
POST/api/v1/activities/createPro/AdminCreate activity
POST/api/v1/activities/updatePro/AdminUpdate activity
DELETE/api/v1/activities/{id}Pro/AdminDelete activity
GET/api/v1/activities/{id}UserActivity detail
GET/api/v1/activities/{id}/deletion-impactAdminDeletion impact
GET/api/v1/activities/{id}/subscription-entitlementUserSubscription entitlement for the activity
GET/api/v1/activities/schedulesUserSchedules (week/day views)
POST/api/v1/activities/availabilityUserSlot availability
POST/api/v1/activities/bookUserCreate a booking
POST/api/v1/activities/cancel-bookUserCancel a booking
POST/api/v1/activities/{activityId}/photosProGallery photos
PUT/api/v1/activities/{activityId}/photos/mainProSet main photo
POST/api/v1/activities/positionsAdminReorder activities
GET/PUT/api/v1/activities/admin-overbooking-configAdminallow_admin_overbooking toggle
POST/api/v1/activities/check-capacity-conflicts(-batch)AdminCapacity guard checks
POST/api/v1/activities/cancel-capacity-changeAdminCancel scheduled capacity change

Admin bookings slot layout, admin override and excess-user tracking are served by these same endpoints plus /api/v1/users/user/{userId}/bookings and /api/v1/users/users-for-schedule.

Locations​

Base: /api/v1/locations.

MethodEndpointAuthDescription
GET/api/v1/locationsUserList locations
GET/api/v1/locations/{id}UserLocation detail
POST/api/v1/locationsAdminCreate location
PUT/api/v1/locations/{id}AdminUpdate location
DELETE/api/v1/locations/{id}AdminDelete location

Closures​

Base: /api/v1/sc (studio closures).

MethodEndpointAuthDescription
GET/api/v1/scUserList closures
GET/api/v1/sc/reasonsUserClosure reasons
POST/api/v1/sc/createAdminCreate closure
POST/api/v1/sc/updateAdminUpdate closure
DELETE/api/v1/sc/{id}AdminDelete closure
POST/PUT/DELETE/api/v1/sc/groups[/{id}]AdminClosure groups

Subscriptions​

MethodEndpointAuthDescription
GET/api/v1/studio-plansProList studio plans
POST/PUT/DELETE/api/v1/studio-plans[/{id}]AdminStudio plan CRUD
PATCH/api/v1/studio-plans/{id}/daily-limitAdminDaily booking limit
PATCH/api/v1/studio-plans/{id}/toggleAdminActivate/deactivate
GET/api/v1/client-subscriptionsPro/AdminList client subscriptions
GET/api/v1/client-subscriptions/statsPro/AdminDashboard stats
GET/api/v1/client-subscriptions/{id}Pro/AdminDetail with check-in history
POST/api/v1/client-subscriptions / batch / customAdminCreate subscriptions
PATCH/api/v1/client-subscriptions/{id}/suspend / validity / reactivate / cancelAdminLifecycle
POST/api/v1/client-subscriptions/{id}/refundAdminRefund
POST/api/v1/client-subscriptions/{id}/check-inAdminCheck in a booking
POST/api/v1/client-subscriptions/{id}/credit-entryAdminCredit an entry
GET/POST/PUT/DELETE/api/v1/subscription-features[/{id}]SuperAdminFeature catalog
GET/POST/PUT/DELETE/api/v1/subscription-plans[/{id}]SuperAdminPlatform plan catalog
GET/POST/PUT/api/v1/organization/subscription[/{id}]Admin/SuperAdminOrganization subscription
GET/api/v1/my/subscription, /my/subscriptions, /my/check-insUserSelf-service view
POST/api/v1/my/check-inUserSelf-service check-in

Payments​

Base: /api/v1/payments (requires enable_online_payments for checkout).

MethodEndpointAuthDescription
GET/api/v1/payments/admin/readinessAdminProvider/flag readiness
POST/api/v1/payments/booking-checkoutUserStart a booking checkout
POST/api/v1/payments/{provider}/webhooknoneProvider webhook (Stripe/PayPal)
GET/api/v1/payments/orders/{id}UserOwn order
GET/api/v1/payments/admin/orders[/{id}]AdminOrder list/detail
POST/api/v1/payments/admin/orders/{id}/reviewAdminReview order
POST/api/v1/payments/orders/{id}/invoice/retryAdminRetry invoice emission

Commerce (Orders)​

Base: /api/v1/commerce.

MethodEndpointAuthDescription
GET/api/v1/commerce/offersUserAvailable offers
POST/api/v1/commerce/studio-plan-checkoutUserBuy a studio plan
GET/api/v1/commerce/ordersUserOwn orders
GET/api/v1/commerce/orders/{id}UserOrder detail
POST/api/v1/commerce/orders/{id}/reconcileUserReconcile payment state
GET/api/v1/commerce/admin/orders[/{id}]AdminAdmin order list/detail
POST/api/v1/commerce/admin/orders/{id}/reviewAdminReview order
POST/api/v1/commerce/admin/orders/{id}/invoice/retryAdminRetry invoice emission

Invoicing (Fatture)​

Base: /api/v1/einvoicing.

MethodEndpointAuthDescription
GET/api/v1/einvoicing/fattureAdminList invoices
POST/api/v1/einvoicing/fattureAdminCreate invoice
POST/api/v1/einvoicing/fatture/importAdminImport incoming invoices
POST/api/v1/einvoicing/fatture/{id}/send / resendAdminSend to SDI
POST/api/v1/einvoicing/fatture/offline/booking/{id} / offline/subscription/{id}AdminOffline invoice
POST/api/v1/einvoicing/fatture/collectiveAdminCollective invoice
GET/api/v1/einvoicing/fatture/export, /{id}/pdf, /{id}/pdf-branded, /{id}/allegati, /{id}/notificaAdminExport/PDF/attachments/notifications
POST/api/v1/einvoicing/fatture/sync, /{id}/syncAdminSync with the gateway
GET/api/v1/einvoicing/fatture/unread-countAdminUnread incoming count
POST/api/v1/einvoicing/fatture/{id}/mark-read, /{id}/forward-emailAdminMark read / forward by email
CRUD/api/v1/einvoicing/aziende[/{id}]SuperAdminCompany registry
GET/PUT/api/v1/einvoicing/settingsAdmin/SuperAdminGateway settings
POST/api/v1/einvoicing/settings/test-connectionAdminTest gateway credentials
GET/PUT/api/v1/einvoicing/billing-profiles/{userId}AdminBilling profile

Blog (Native + Legacy)​

Native blog (gated by enable_native_blog), generated controllers:

MethodEndpointAuthDescription
CRUD/api/v1/articles[/{id}]ProArticles (drafts, publish/unpublish, bulk)
GET/api/v1/articles/admin/by-locale/{locale}, /admin/allProAdmin listings
CRUD/api/v1/categories[/{id}], /api/v1/authors[/{id}]ProCategories and authors
GET/api/v1/comments, /comments/reportsProComment moderation
PATCH/DELETE/api/v1/comments/{commentId}ProApprove/block/delete comments
POST/api/v1/comments/reports/{reportId}/resolveProResolve a report

Legacy Strapi-backed blog (gated by enable_blogs):

MethodEndpointAuthDescription
GET/api/v1/strapi-comments/flatAdminFlat comment list from Strapi
PUT/api/v1/strapi-comments/{commentId}/approve / block / unblockAdminModeration

Public blog reads: /api/public/v1/articles (article.read), /articles/by-slug/{slug}, /authors (author.read), /categories (category.read); public comments: /api/public/v1/comments/article/{articleId} (GET/POST, Turnstile) and /comments/{commentId}/report.

Immobili​

MethodEndpointAuthDescription
CRUD/api/v1/immobiles[/{id}]ProReal-estate entities (generated; custom validation)
GET/api/v1/immobili/matching/{immobileId}ProMatching preferences
PUT/api/v1/immobili/matching/{immobileId}/preference/{preferenceId}/statusProPreference status
CRUD/api/v1/immobili/preferences/...ProPreference templates and per-user/contact preferences
GET/api/v1/immobili/users/{id}/access-historyProAccess history
POST/api/v1/public/immobili/grant-accesscookie/bearerGrant client access (accepts terms, logs first access)
GET/api/v1/public/immobili/check-access/{immobileId}cookie/bearerCheck access (logs each visit)
POST/api/v1/public/immobili/accept-termscookie/bearerAccept terms / newsletter preferences

Public API: /api/public/v1/immobiles (immobile.read).

MethodEndpointAuthDescription
CRUD/api/v1/catalog-items[/{id}]ProCatalog entities (generated)
GET/api/v1/catalog-items/categoriesProCategories
CRUD/api/public/v1/catalog-items[/{id}]tokenPublic CRUD (catalog-item.read / catalog-item.write)
POST/api/public/v1/catalog-items/bulk-delete / bulk-publish / bulk-unpublishtokenBulk operations
GET/api/public/v1/catalog-items/published, /by-slug/{slug}token/nonePublished items
POST/api/public/v1/catalog-items/{id}/attachments/presign / confirmtokenAttachment upload

Galleries & Dynamic Contents (+ History)​

Base: /api/v1/galleries (reads available to User; Pro needs the website.gallery access permission).

MethodEndpointAuthDescription
GET/api/v1/galleries[/{id}]User/ProList/detail
POST/PUT/DELETE/api/v1/galleries[/{id}]ProCreate/update/delete
POST/DELETE/api/v1/galleries/{galleryId}/mediaProAdd/remove media
GET/api/v1/galleries/{id}/versions[/{versionId}]ProContent history (requires enable_content_history)
POST/api/v1/galleries/{id}/versions/{versionId}/restoreProRestore a version
DELETE/api/v1/galleries/{id}/versions/{versionId}ProDelete a version
GET/PUT/api/v1/galleries/structure-lockSuperAdmin_system_lock_dynamic_content_structure
GET/POST/DELETE/PUT/api/v1/galleries/{id}/attachments[...]ProAttachments (confirm, reorder, public toggle)
GET/api/public/v1/galleries/{id}token (galleries.read)Public gallery

Dynamic entity CRUD is generated per bounded context (/api/v1/immobiles, /api/v1/catalog-items, …) from Flo.BE/Schemas/*; see Dynamic Entities.

Website States​

MethodEndpointAuthDescription
GET/PUT/api/v1/website-statesProLocalized date-based states
GET/api/public/v1/website-statetoken (website-states.read)Public state

Forms (Admin + Public Submit)​

Admin (enable_public_forms):

MethodEndpointAuthDescription
GET/api/v1/forms, /forms/overviewProList forms / overview
POST/PUT/api/v1/forms[/{id}]ProCreate/update form
POST/api/v1/forms/{id}/publishProPublish
GET/api/v1/forms/submissions[/{submissionId}], /forms/audit, /forms/exportProSubmissions, audit, export
PUT/api/v1/forms/submissions/{id}/status / contact / legal-holdProTriage
DELETE/api/v1/forms/submissions/{id}ProDelete submission
GET/PUT/api/v1/forms/settingsAdminForm settings

Public: GET /api/public/v1/forms/{slug}, POST /api/public/v1/forms/{slug}/files/presign, POST /api/public/v1/forms/{slug}/files/{fileId}/confirm, POST /api/public/v1/forms/{slug}/submissions (forms.read / forms.write, Turnstile required).

Contacts​

Base: /api/v1/contacts (Communication module).

MethodEndpointAuthDescription
GET/api/v1/contactsProList contacts
GET/api/v1/contacts/categories, /labelsProCategories and labels
POST/PUT/DELETE/api/v1/contacts[/{id}]ProContact CRUD
POST/api/v1/contacts/import/preview / importProCSV import
GET/POST/api/v1/contacts/import/undoProUndo an import
GET/api/v1/contacts/importable-usersProUsers importable as contacts
DELETE/api/v1/contactsProBulk delete

Communication & Newsletter​

Base: /api/v1/newsletter (Pro base; settings and quota operations are Admin/SuperAdmin).

MethodEndpointAuthDescription
GET/POST/PUT/DELETE/api/v1/newsletter/get-all, create, update, {id}ProSubscriber CRUD
POST/api/v1/newsletter/import / sendProImport subscribers / send
GET/api/v1/newsletter/template, /templates/list, /templates/composable, /templates/{name}/previewProTemplate registry/preview
GET/api/v1/newsletter/messages, /messages/library, /messages/{id}ProMessage editor/library
POST/PUT/DELETE/api/v1/newsletter/messages/...ProDraft, confirm, edit, duplicate, clear, delete
GET/api/v1/newsletter/send-jobs[/{id}], /preflight, /previewProSend jobs
POST/api/v1/newsletter/send-jobs/{id}/cancelProCancel a job
POST/api/v1/newsletter/custom/preview / custom/sendProComposed newsletter
GET/PUT/api/v1/newsletter/settingsSuperAdminProvider/quota settings
GET/PUT/api/v1/newsletter/auto-configAdminAutomations config
GET/PUT/api/v1/newsletter/double-opt-inAdminDouble opt-in
POST/api/v1/newsletter/settings/reset-quotaSuperAdminReset the monthly quota
POST/api/v1/newsletter/unsubscribe / resubscribe, suppressionsnone/ProOpt-out handling
POST/api/public/v1/newsletter/subscribe, GET /confirm, POST /unsubscribe/one-clicknone (newsletters.write)Public subscribe/confirm/unsubscribe

Translations​

MethodEndpointAuthDescription
GET/api/v1/translation/statusPro/AdminProvider status
POST/api/v1/translation/translatePro/AdminTranslate content (Ollama/DeepL)

Branding​

MethodEndpointAuthDescription
GET/api/v1/admin/brandingPro/SuperAdminEffective branding config
PUT/api/v1/admin/branding/theme, /brand-meta, /pwa, /loginSuperAdminBranding sections
POST/DELETE/api/v1/admin/branding/assets, /pwa-assets, /login-assetsSuperAdminBranding assets
GET/PUT/api/v1/brand-kit, /brand-kit/libraryProBrand kit and library
GET/PUT/api/v1/config-editor/keys, /theme, /brand-config, /whitelabelSuperAdminLow-level config editor
GET/api/public/v1/brandingnonePublic branding bootstrap

Analytics​

MethodEndpointAuthDescription
GET/api/v1/analytics/counters, /counters/{category}/{name}/today, /statisticsAdminRaw counters
GET/api/v1/analytics/summary, /dashboard, /categories, /categories/{category}/namesAdminDashboard and categories
GET/api/v1/analytics/pwa-installed-users[/export]AdminPWA adoption
DELETE/api/v1/analytics/purgeSuperAdminPurge counters
GET/api/v1/business-analytics/dashboardAdmin/ProBusiness KPIs
GET/api/v1/web-analytics/dashboard, /overview, /timeseries, /breakdown, /search, /statusAdmin/ProGA4/GSC dashboard
GET/PUT/POST/api/v1/web-analytics/config, /config/test, /backfillAdminAnalytics configuration

Settings​

MethodEndpointAuthDescription
GET/api/v1/admin/feature-flagsnone (bootstrap)Feature flags (no-store)
POST/api/v1/admin/feature-flagsAdminSave flags
POST/api/v1/admin/invalidate-sessionsAdminInvalidate all sessions
GET/api/v1/admin/configsnone (bootstrap)Registration/login branding/storage config
GET/POST/PUT/DELETE/api/v1/api-tokens[/{id}], /permissionsSuperAdminPublic API tokens
GET/POST/PUT/DELETE/api/v1/webhook-configs[/{id}], /entity/{entityName}SuperAdminWebhooks (+ /trigger, /{id}/test)
CRUD/api/v1/cors-origins[/{id}], /active, /initializeSuperAdminDB-backed CORS origins
GET/api/v1/audit-logs, /export-query, /entity/{entityName}/{entityId}, /user/{userId}AdminAudit trail
GET/POST/PUT/DELETE/api/v1/audit-logs/export/user/{userId}, /anonymize/user/{userId}, /retention, /purgeSuperAdminGDPR/retention operations
POST/api/v1/auth-events/clientnoneClient auth event beacon
GET/api/v1/auth-eventsSuperAdminAuth event list
GET/api/v1/email-delivery-logs[/availability]SuperAdminEmail delivery log viewer
GET/api/v1/logs, /user/{userId}, `/export/csvjson, /periods, /diagnostic, /levels`SuperAdmin
GET/api/v1/quotasAdminMetered resource quotas
POST/api/v1/maintenance/purge-users, /email/replay-failed, /mode, /feature-flags/invalidate, /auth/invalidate-sessionsX-Maintenance-KeyOperations endpoints
GET/PUT/api/v1/localization/settingsAdmin/SuperAdminContent languages
GET/api/v1/sidebar/configauthenticatedServer-driven sidebar
GET/api/v1/schema, /schema/entities, /schema/augmented[/{name}], /schema/entities/{name}Admin/SuperAdminSchema metadata
CRUD/api/v1/enum-values/...AdminEnum value management
GET/api/v1/geographic/province, /comuni, /capUserGeographic reference data
POST/api/v1/pwa/heartbeatauthenticatedPWA install heartbeat
GET/manifest.webmanifestnonePWA manifest
POST/api/v1/storage/presign, /upload, /confirm, /renameUserUpload flow (see Media Storage)
POST/api/v1/media-scan/run / cancelSuperAdminTrigger/cancel a media compatibility scan
GET/api/v1/media-scan/status / runsAdmin/SuperAdminScan status and run history
GET/api/v1/media-scan/flaggedProFlagged media (all types or one)

Diagnostics & Health​

MethodEndpointAuthDescription
GET/api/v1/diagnostics/versionauthenticatedVersion, commit, branch, build time
GET/api/v1/diagnostics/appsettings/development / productionSuperAdminEffective configuration (redacted)
GET/healthnoneLiveness + DB check
GET/health/readynoneReadiness
GET/health/commercenoneCommerce readiness

Response Caching​

GET endpoints use HTTP Cache-Control via [ResponseCache]. There is no server-side output cache; booking-boundary reads are explicitly forbidden from using one.

DurationData TypeExamples
24hStatic reference dataGeographic province/CAP, analytics categories and names, log periods/levels
1hNear-static dataGeographic comuni, diagnostics version, immobile preference templates
10minSchema metadataGeneric schema endpoint (cookie-varying)
No cacheReal-time / flow-critical dataAuth, feature flags, admin configs, schema admin endpoints, locations, home/sidebar, website states, branding, organizations, user data, mutations

API Versioning​

All endpoints use URL-based versioning:

/api/v{version:apiVersion}/resource

Controllers use the [ApiVersion] attribute:

[ApiVersion("1.0")]
[Route("api/v{version:apiVersion}/locations")]
public class LocationController : ControllerBase

X-Api-Version is also accepted as a header.

TypeScript Client Generation​

The frontend uses auto-generated TypeScript clients from the OpenAPI spec:

cd Flo.FE
npm run generate-proxies

This produces:

  • src/app/services/client.ts — Private API client with all DTOs
  • src/app/services/public-api-client.ts — Public API client

Run this command whenever backend endpoints change (requires the backend running on localhost:10001).

Public API Tokens​

External consumers can access public endpoints using API tokens:

  1. SuperAdmin creates tokens in Settings > API Tokens
  2. Tokens are scoped to permissions (e.g. activities.read, media.write) and validated against the request Origin/Referer
  3. Rate-limited at the Nginx layer and by application-level limiters (presign, media upload, public browser flows)
  4. Token is passed via Authorization: Bearer <token> header

Public API groups: activities, professionals, galleries, media, attachments, forms, newsletter, website-state, branding, localization, articles/authors/categories/comments, catalog-items, immobiles.

Swagger​

In development, Swagger UI is available at /swagger with two specs:

  • Private API: /swagger/v1/swagger.json
  • Public API: /swagger/public-v1/swagger.json